< Back to all clusters
[TECHNOLOGY] · Australia, China · 2 sources

started · updated

Cybersecurity vulnerabilities exposed in connected BYD and Xpeng vehicles

An investigation by ABC News in Australia has highlighted significant cybersecurity vulnerabilities in modern connected vehicles. Cybersecurity expert Dan Hreszczuk demonstrated the ability to remotely control various components of a BYD Shark 6 without needing passwords. During the experiment, the hacker was able to activate windshield wipers, play music through speakers, turn off vehicle lights, and record audio via the car’s microphone and Siri interface.

Further demonstrations involving Xpeng vehicles showed that remote access could allow unauthorized parties to view sensitive data, including location, speed, steering angle, seat position, and the number of occupants. While Xpeng stated that their vehicles cannot be disabled or stopped remotely and denied providing Australian customer data to Chinese authorities, the findings have raised concerns regarding the scope of data collection.

The Australian Automobile Dealers Association (AADA) noted that consumers are increasingly concerned about the types of information vehicles collect, how that data is protected, and which functions can be accessed remotely. Modern vehicles generate vast amounts of data—ranging from driving habits to camera and microphone recordings—which are often transmitted to manufacturer servers or cloud systems rather than being stored solely on the vehicle.

Entities

ABC News · Australian Automobile Dealers Association · BYD · Dan Hreszczuk · XPeng